I have inherited a medium install of Splunk, and for the most part, I understand everything. But, a simple account locked alert is sending multiple, multiple email notices per minute, and I don't understand why. I'll include a screenshot so anyone who sees something let me know. The purpose is to check for real-time account lockouts and notify only once.
Probably its because of real-time alert. You can schedule it to run every 1 min for the window of last 60 seconds i.e. 1 minute.
Perfect guys thank you!
In addition to the great answer from @Vijeta, turn on throttling. This keeps Splunk from generating additional alerts for the same event(s) for a period of time. To do that, click on the "Throttle" box, complete the form, and click Save.
The throttling did it, thank you, guys!
Probably its because of real-time alert. You can schedule it to run every 1 min for the window of last 60 seconds i.e. 1 minute.
Ok good. Thank you, clearly, I'm very new to Splunk in general.